`ZstdCompressionWriter()` constructs successfully but leads to `segmentation fault`
维护者通常 2 天内回复
还没有人认领这个 Issue。
评估
调研方向
先运行 Python reproducer,然后结合 writer 的构造路径检查 c-ext/compressionwriter.c:64 和 c-ext/decompressionwriter.c:50。比较 C extension 与 CFFI backend 在无参数构造时的行为。完成的标准是:直接构造不再留下可访问的 NULL 内部字段,并且抛出 Python exception,而不是发生 segfault。
由索引模型根据 Issue 内容生成。
描述
I've been fuzzing Python C extension modules for a small research project.
I found a sanitizer issue which is a null-pointer dereference in ZstdCompressionWriter_memory_size.
I reproduced it with the binary wheel from a plain pip install zstandard.
The process terminates with SIGSEGV there as well.
I'm not sure whether zero-argument construction of this type is considered supported (calling ZstdCompressionWriter() with no arguments),
but since it currently terminates the interpreter rather than raising a Python exception, I thought it was worth reporting.
Versions
zstandard 0.25.0, cext backend, CPython 3.12, Linux x86_64.
Reproducer
import zstandard
w = zstandard.ZstdCompressionWriter() # succeeds
w.memory_size() # SIGSEGV
Five calls across the two writer types behave the same way, each from a fresh direct construction:
| class | methods that segfault |
|---|---|
ZstdCompressionWriter |
memory_size(), close(), flush() |
ZstdDecompressionWriter |
memory_size(), flush() |
Sanitizer build
Same call, zstandard built with -fsanitize=address,undefined:
c-ext/compressionwriter.c:64:65: runtime error:
member access within null pointer of type 'ZstdCompressor'
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior
c-ext/compressionwriter.c:64:65
AddressSanitizer: SEGV on unknown address 0x000000000020
#0 ZstdCompressionWriter_memory_size c-ext/compressionwriter.c:64:65
ZstdDecompressionWriter.memory_size() reports the equivalent at
c-ext/decompressionwriter.c:50:67.
Expected behavior
I think that direct construction should be rejected with a Python exception, as it is by the CFFI backend.
Under PYTHON_ZSTANDARD_IMPORT_POLICY=cffi the same construction is refused outright:
TypeError: ZstdCompressionWriter.__init__() missing 5 required positional
arguments: 'compressor', 'writer', 'source_size', 'write_size',
and 'write_return_read'
Actual behavior
The C extension permits construction with no arguments, leaving internal fields NULL.
Several methods dereference those fields and terminate the process with SIGSEGV.
Although these objects are normally obtained through stream_writer(), I wonder whether the C extension should reject zero-argument construction, as the CFFI backend already does, rather than produce an uninitialized object.
- 主要语言
- C
- 星标
- 641
- 派生
- 117
- 平均合并
- 1 天 14 小时
- 30 天内合并 PR
- 5
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
indygreg/python-zstandard 的其他 Issue
-
`multi_decompress_to_buffer([])` terminates the process with SIGFPE可能已有人在做 @mikamikasuki 于 7 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
indygreg/python-zstandard#335 ·
维护者通常 2 天内回复
-
Silent data-correctness bug: `readinto()` / `readinto1()` on `stream_reader` return `tell() == 0` after successful reads可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 76/100
indygreg/python-zstandard#295 ·
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 64/100
indygreg/python-zstandard#345 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 55/100
indygreg/python-zstandard#334 ·
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 54/100
indygreg/python-zstandard#333 ·
维护者通常 2 天内回复
查看 indygreg/python-zstandard 的全部 Issue
相似的 Issue
-
enhancement good first issue
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
NASA-AMMOS/BSL#355 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 78/100
arancormonk/dsd-neo#660 ·
维护者通常 1 天内回复
-
[Bug]: remote-ls --updates reports up-to-date OCI refs because it ignores deployed Alt-id可能已有人在做 @Joao-kouznetz 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复